Back to overview

CVE-2026-64395

Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate extents FSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to vfs_clone_file_range() or vfs_copy_file_range() without checking the SMB access mask granted to the source handle. A handle opened with attribute access can consequently be used to copy file contents into an attacker-readable destination. Require FILE_READ_DATA on the source handle before either VFS operation, matching other ksmbd data-copy paths.

Metadata

CVE ID
CVE-2026-64395
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:50 UTC
Last updated
2026-07-25 08:50 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2d2ab6983620c2d60ce7db72133984ca3873b929, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 67bdad9cf01b25030e3bf00bbce6c309319d6663, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < db231af842868268839f9f9619c68cb27830d8be …
Linux Linux 6.1.178 ≤ 6.1.*, 6.6.145 ≤ 6.6.*, 6.12.96 ≤ 6.12.*, 6.18.39 ≤ 6.18.* …
Back to overview